Candidate: CVE-2020-15562 PublicDate: 2020-07-06 12:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15562 https://github.com/roundcube/roundcubemail/commit/3e8832d029b035e3fcfb4c75839567a9580b4f82 https://github.com/roundcube/roundcubemail/releases/tag/1.2.11 https://github.com/roundcube/roundcubemail/releases/tag/1.3.14 https://github.com/roundcube/roundcubemail/releases/tag/1.4.7 Description: An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML namespace) attribute of a HEAD element when an SVG element exists. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=964355 Priority: medium Discovered-by: Andrea Cardaci Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_roundcube: upstream: https://github.com/roundcube/roundcubemail/commit/f3d1566cf223eb04f47b6dfffcd88753f66c36ee (1.2.x) upstream: https://github.com/roundcube/roundcubemail/commit/19502419757a976dbd55ce5a746610c5bab7896b (1.3.x) upstream: https://github.com/roundcube/roundcubemail/commit/3e8832d029b035e3fcfb4c75839567a9580b4f82 (1.4.x) upstream_roundcube: released (1.2.11, 1.3.14, 1.4.7) precise/esm_roundcube: DNE trusty_roundcube: ignored (out of standard support) trusty/esm_roundcube: DNE xenial_roundcube: ignored (end of standard support, was needed) bionic_roundcube: needed eoan_roundcube: ignored (reached end-of-life) focal_roundcube: needed groovy_roundcube: not-affected (1.4.7+dfsg.1-1) hirsute_roundcube: not-affected (1.4.7+dfsg.1-1) impish_roundcube: not-affected (1.4.11+dfsg.1-4) jammy_roundcube: not-affected (1.5.0+dfsg.1-2) devel_roundcube: not-affected (1.5.0+dfsg.1-2)